Spear-Phishing and POWERSTAT: Dissecting MuddyWater's Latest Middle East Attacks
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Downloader,Dropper,Malicious Macro,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: Low Impact/Low Probability
Threat Overview
In late November 2018, the Iranian APT group MuddyWater launched a new series of attacks in Middle East countries, targeting Lebanon, Oman, and Turkey. The campaign, consistent with their previous tactics since 2017, utilized spear-phishing emails with blurred documents to trick victims into enabling VB-macro code, subsequently infecting hosts with POWERSTAT malware. The attack involved creating a malicious Excel document for downloading further payloads, using PowerShell and JavaScript for execution delays, and establishing persistence through registry modifications and scheduled tasks. The POWERSTAT backdoor facilitated data exfiltration and remote command execution, highlighting MuddyWater's continued reliance on scripting languages and system tools for their objectives.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Lebanon | Verified |
| Region | Oman | Verified |
| Region | Turkey | Verified |
Extracted IOCs
- amorenvena[.]com
- amphira[.]com
- pazazta[.]com
- 077bff76abc54edabda6b7b86aa1258fca73db041c53f4ec9c699c55a0913424
- 294a907c27d622380727496cd7c53bf908af7a88657302ebd0a9ecdd30d2ec9d
- 79f2d06834a75981af8784c2542e286f1ee757f7a3281d3462590a89e8e86b5a
- ae2c0de026d0df8093f4a4e2e2e4d297405f943c42e86d3fdd0ddea656c5483d
- ccfdfcee9f073430cd288522383ee30a7d6d3373b968f040f89ae81d4772a7d0
- 139[.]162.245.200
- hxxp://amphira[.]com
- hxxp://pazazta[.]com/app/icon.png
- hxxps://amorenvena[.]com
Tip: 12 related IOCs (1 IP, 3 domain, 3 URL, 0 email, 5 file hash) to this threat have been found.
Overlaps
Source: Picussecurity - March 2022
Detection (one case): 294a907c27d622380727496cd7c53bf908af7a88657302ebd0a9ecdd30d2ec9d
Source: ClearSky - November 2018
Detection (five cases): hxxp://pazazta[.]com/app/icon.png, 294a907c27d622380727496cd7c53bf908af7a88657302ebd0a9ecdd30d2ec9d, amorenvena[.]com, amphira[.]com, pazazta[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
MuddyWater Cyberattack Campaign
A targeted cyberattack campaign was detected utilizing malicious document attachments to infect organizations with a backdoor program called POWERSTAT. The attackers used blurred document previews to trick recipients into enabling embedded macros, initiating a multi-stage infection sequence.
The campaign was conducted by an Iranian threat group known as "MuddyWater," which has been active since at least 2017. The group is recognized for targeted cyber operations in the Middle East, frequently employing social engineering tactics and macro-based document lures.
The primary goal was to establish persistent access on compromised target machines to gather intelligence and execute remote commands. The attackers sought to monitor compromised systems, run scripts, and exfiltrate operational details.
This was a targeted cyber attack rather than a widespread campaign aimed at the general public. The targeting specifically focused on institutional entities located in Lebanon, Oman, and Turkey.
Institutional targets hold strategic geopolitical data and organizational intelligence. Establishing long-term foothold access inside these systems allows foreign threat actors to conduct ongoing monitoring and data collection.
Victims received spear-phishing emails containing blurred Word files, such as fake resume documents. Once the victim enabled macros, the document displayed a fake software error message while secretly executing background scripts to download and run the POWERSTAT backdoor malware.
Organizations should block macro execution by default, monitor system execution tools like PowerShell and CSCRIPT, and block known malicious domains and IP addresses. Individuals should avoid enabling macros on unexpected email attachments and report unusual document behavior to IT security teams.